First published: Fri Feb 21 2020(Updated: )
Gogs through 0.11.91 allows attackers to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gogs Gogs | <=0.11.91 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9329 is a vulnerability in Gogs through version 0.11.91 that allows attackers to violate the admin-specified repo-creation policy due to a race condition.
CVE-2020-9329 has a severity level of medium with a CVSS score of 5.9.
Attackers can exploit CVE-2020-9329 by taking advantage of the internal/db/repo.go race condition in Gogs.
To fix CVE-2020-9329, you should update Gogs to a version beyond 0.11.91.
You can find more information about CVE-2020-9329 on the official GitHub issue page: https://github.com/gogs/gogs/issues/5926